<!DOCTYPE html>












  


<html class="theme-next gemini use-motion" lang="en">
<head><meta name="generator" content="Hexo 3.8.0">
  <meta charset="UTF-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=2">
<meta name="theme-color" content="#222">


























<link rel="stylesheet" href="/lib/font-awesome/css/font-awesome.min.css?v=4.6.2">

<link rel="stylesheet" href="/css/main.css?v=7.0.0">


  <link rel="apple-touch-icon" sizes="180x180" href="/images/apple-touch-icon-next.png?v=7.0.0">


  <link rel="icon" type="image/png" sizes="32x32" href="/images/favicon-32.ico?v=7.0.0">


  <link rel="icon" type="image/png" sizes="16x16" href="/images/favicon-16.ico?v=7.0.0">


  <link rel="mask-icon" href="/images/logo.svg?v=7.0.0" color="#222">







<script id="hexo.configurations">
  var NexT = window.NexT || {};
  var CONFIG = {
    root: '/',
    scheme: 'Gemini',
    version: '7.0.0',
    sidebar: {"position":"left","display":"post","offset":12,"b2t":false,"scrollpercent":true,"onmobile":false},
    fancybox: false,
    fastclick: false,
    lazyload: false,
    tabs: true,
    motion: {"enable":true,"async":false,"transition":{"post_block":"fadeIn","post_header":"slideDownIn","post_body":"slideDownIn","coll_header":"slideLeftIn","sidebar":"slideUpIn"}},
    algolia: {
      applicationID: '',
      apiKey: '',
      indexName: '',
      hits: {"per_page":10},
      labels: {"input_placeholder":"Search for Posts","hits_empty":"We didn't find any results for the search: ${query}","hits_stats":"${hits} results found in ${time} ms"}
    }
  };
</script>


  




  <meta name="description" content="HSTS是把双刃剑，但是当SSL证书并不是通配符证书时，子域名等都是无法访问的。">
<meta name="keywords" content="JavaWeb,SpringBoot,SpringSecurity,HSTS,HTTPS">
<meta property="og:type" content="article">
<meta property="og:title" content="踩坑记：HSTS导致子域名无法访问">
<meta property="og:url" content="https://blog-test.jetchen.cn/reject-hsts/index.html">
<meta property="og:site_name" content="嘎里三分熟">
<meta property="og:description" content="HSTS是把双刃剑，但是当SSL证书并不是通配符证书时，子域名等都是无法访问的。">
<meta property="og:locale" content="en">
<meta property="og:image" content="http://blogsource.chenkaikai.com/uploads/image/20180831/1535682578757311.png">
<meta property="og:image" content="http://blogsource.chenkaikai.com/uploads/image/20180831/1535683032535508.png">
<meta property="og:image" content="http://blogsource.chenkaikai.com/uploads/image/20180831/1535683044828173.png">
<meta property="og:image" content="http://blogsource.chenkaikai.com/uploads/image/20180831/1535683071116194.png">
<meta property="og:image" content="http://blogsource.chenkaikai.com/uploads/image/20180831/1535686972560553.png">
<meta property="og:image" content="http://blogsource.chenkaikai.com/uploads/image/20180831/1535687276938022.png">
<meta property="og:image" content="http://blogsource.chenkaikai.com/uploads/image/20180831/1535688197240240.png">
<meta property="og:image" content="http://blogsource.chenkaikai.com/uploads/image/20180831/1535690627829085.png">
<meta property="og:updated_time" content="2019-02-25T15:30:28.000Z">
<meta name="twitter:card" content="summary">
<meta name="twitter:title" content="踩坑记：HSTS导致子域名无法访问">
<meta name="twitter:description" content="HSTS是把双刃剑，但是当SSL证书并不是通配符证书时，子域名等都是无法访问的。">
<meta name="twitter:image" content="http://blogsource.chenkaikai.com/uploads/image/20180831/1535682578757311.png">






  <link rel="canonical" href="https://blog-test.jetchen.cn/reject-hsts/">



<script id="page.configurations">
  CONFIG.page = {
    sidebar: "",
  };
</script>

  <title>踩坑记：HSTS导致子域名无法访问 | 嘎里三分熟</title>
  












  <noscript>
  <style>
  .use-motion .motion-element,
  .use-motion .brand,
  .use-motion .menu-item,
  .sidebar-inner,
  .use-motion .post-block,
  .use-motion .pagination,
  .use-motion .comments,
  .use-motion .post-header,
  .use-motion .post-body,
  .use-motion .collection-title { opacity: initial; }

  .use-motion .logo,
  .use-motion .site-title,
  .use-motion .site-subtitle {
    opacity: initial;
    top: initial;
  }

  .use-motion .logo-line-before i { left: initial; }
  .use-motion .logo-line-after i { right: initial; }
  </style>
</noscript>

</head>

<body itemscope itemtype="http://schema.org/WebPage" lang="en">

  
  
    
  

  <div class="container sidebar-position-left page-post-detail">
    <div class="headband"></div>

    <header id="header" class="header" itemscope itemtype="http://schema.org/WPHeader">
      <div class="header-inner"><div class="site-brand-wrapper">
  <div class="site-meta">
    

    <div class="custom-logo-site-title">
      <a href="/" class="brand" rel="start">
        <span class="logo-line-before"><i></i></span>
        <span class="site-title">嘎里三分熟</span>
        <span class="logo-line-after"><i></i></span>
      </a>
    </div>
    
    
  </div>

  <div class="site-nav-toggle">
    <button aria-label="Toggle navigation bar">
      <span class="btn-bar"></span>
      <span class="btn-bar"></span>
      <span class="btn-bar"></span>
    </button>
  </div>
</div>



<nav class="site-nav">
  
    <ul id="menu" class="menu">
      
        
        
        
          
          <li class="menu-item menu-item-home">

    
    
    
      
    

    

    <a href="/" rel="section"><i class="menu-item-icon fa fa-fw fa-home"></i> <br>Home</a>

  </li>
        
        
        
          
          <li class="menu-item menu-item-about">

    
    
    
      
    

    

    <a href="/about-me/" rel="section"><i class="menu-item-icon fa fa-fw fa-user"></i> <br>About</a>

  </li>
        
        
        
          
          <li class="menu-item menu-item-archives">

    
    
    
      
    

    

    <a href="/archives/" rel="section"><i class="menu-item-icon fa fa-fw fa-archive"></i> <br>Archives</a>

  </li>

      
      
    </ul>
  

  

  
</nav>



  



</div>
    </header>

    


    <main id="main" class="main">
      <div class="main-inner">
        <div class="content-wrap">
          
            

          
          <div id="content" class="content">
            

  <div id="posts" class="posts-expand">
    

  

  
  
  

  

  <article class="post post-type-normal" itemscope itemtype="http://schema.org/Article">
  
  
  
  <div class="post-block">
    <link itemprop="mainEntityOfPage" href="https://blog-test.jetchen.cn/reject-hsts/">

    <span hidden itemprop="author" itemscope itemtype="http://schema.org/Person">
      <meta itemprop="name" content="Jet Chen">
      <meta itemprop="description" content>
      <meta itemprop="image" content="/images/avatar.gif">
    </span>

    <span hidden itemprop="publisher" itemscope itemtype="http://schema.org/Organization">
      <meta itemprop="name" content="嘎里三分熟">
    </span>

    
      <header class="post-header">

        
        
          <h1 class="post-title" itemprop="name headline">踩坑记：HSTS导致子域名无法访问

              
            
          </h1>
        

        <div class="post-meta">
          <span class="post-time">

            
            
            

            
              <span class="post-meta-item-icon">
                <i class="fa fa-calendar-o"></i>
              </span>
              
                <span class="post-meta-item-text">Posted on</span>
              

              
                
              

              <time title="Created: 2018-08-31 12:48:06" itemprop="dateCreated datePublished" datetime="2018-08-31T12:48:06+08:00">2018-08-31</time>
            

            
          </span>

          
            <span class="post-category">
            
              <span class="post-meta-divider">|</span>
            
              <span class="post-meta-item-icon">
                <i class="fa fa-folder-o"></i>
              </span>
              
                <span class="post-meta-item-text">In</span>
              
              
                <span itemprop="about" itemscope itemtype="http://schema.org/Thing"><a href="/categories/Spring基础/" itemprop="url" rel="index"><span itemprop="name">Spring基础</span></a></span>

                
                
                  , 
                
              
                <span itemprop="about" itemscope itemtype="http://schema.org/Thing"><a href="/categories/Spring基础/踩坑记/" itemprop="url" rel="index"><span itemprop="name">踩坑记</span></a></span>

                
                
              
            </span>
          

          
            
            
          

          
          

          

          

          

        </div>
      </header>
    

    
    
    
    <div class="post-body" itemprop="articleBody">

      
      

      
        <p><center>HSTS是把双刃剑，但是当SSL证书并不是通配符证书时，子域名等都是无法访问的。</center><br><a id="more"></a></p>
<h2>一、背景<br></h2>

<p>&nbsp;&nbsp;&nbsp;&nbsp;项目A是二级域名，并且使用 HTTPS 访问，</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;子项目B使用的是基于该二级域名的三级域名，仅使用 HTTP 访问，<br></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;但是上线后发现项目B访问的时候出现下图的错误。</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<img src="http://blogsource.chenkaikai.com/uploads/image/20180831/1535682578757311.png" title="1535682578757311.png" alt="reject-hsts01.png"></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;点开高级，会看到下图的信息，见红框中的 HSTS，<br></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<img src="http://blogsource.chenkaikai.com/uploads/image/20180831/1535683032535508.png" title="1535683032535508.png" alt="reject-hsts02.png"></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;另外，查看控制台的 network，产生了两次请求，而且第一次请求居然被 307了，黑人问号脸？<br></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<img src="http://blogsource.chenkaikai.com/uploads/image/20180831/1535683044828173.png" title="1535683044828173.png" alt="reject-hsts03.png"></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;然后查看项目A的 network，发现 response headers 中有 HSTS 的信息。<br></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<img src="http://blogsource.chenkaikai.com/uploads/image/20180831/1535683071116194.png" title="1535683071116194.png" alt="reject-hsts04.png"></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;好了，所有的证据都指向一个点：HSTS，所以就来搞清楚这个 HSTS 待敌是啥玩意儿。<br></p>
<p><br></p><p></p>
<h2>二、知识点</h2>

<p>&nbsp;&nbsp;&nbsp;&nbsp;1、什么是 HSTS<br></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;国际互联网工程组织IETF正在推行一种新的Web安全协议</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;全称是：HTTP Strict Transport Security</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;作用：简言之就是<strong>浏览器端会将 http 请求强制转为 https 请求</strong>，从此服务器端再也不要再进行重定向操作了。</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;开启：当客户端发起 HTTPS 请求后，服务端返回的超文本传输协议响应头中包含 Strict-Transport-Security 字段，</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;如：Strict-Transport-Security: max-age=31536000; includeSubDomains</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;这说明：① 在未来的&nbsp;<span style="font-size: 14px;">31536000秒（一年）</span>内，HSTS 都是生效的，即该域名的 http 请求都将自动转为 https 请求；②&nbsp;<span style="font-size: 14px;">includeSubDomains 意味着该域名下的所有子域名也都会采用 https 请求</span></p>
<p><span style="font-size: 14px;">&nbsp;&nbsp;&nbsp;&nbsp;2、弊端<br></span></p>
<p><span style="font-size: 14px;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;① 当&nbsp;<span style="font-size: 14px;">Strict-Transport-Security 还未过期，但是域名的证书已经过期了，此时处于 HSTS 考虑，浏览器仍然会采用 https 的方式访问，即会提示不安全</span></span></p>
<p><span style="font-size: 14px;"><span style="font-size: 14px;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;② 当主域名的证书并不是通配符证书时，此时子域名会强制走 HSTS，所以也会提示不安全，无法访问<br></span></span></p>
<p><span style="font-size: 14px;"><span style="font-size: 14px;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;③ 虽然 HSTS 有效抵御了一些不安全的问题（下文会提到），即所有的请求都是走的 HTTPS，但是首次访问的时候走的是 HTTP 协议（暂不考虑Preload List），黑客也是有机可乘的<br></span></span></p>
<p><span style="font-size: 14px;"><span style="font-size: 14px;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;④&nbsp;<span style="font-size: 14px;">Strict-Transport-Security 过期之后的首次请求，走的又是 HTTP 协议</span></span></span></p>
<p><span style="font-size: 14px;"><span style="font-size: 14px;">&nbsp;&nbsp;&nbsp;&nbsp;3、优势<br></span></span></p>
<p><span style="font-size: 14px;"><span style="font-size: 14px;">&nbsp; &nbsp; &nbsp; &nbsp; 不仅仅是优势，其实也是最大的安全技术：<strong>HSTS可以用来抵御SSL剥离攻击。</strong></span></span></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;何为SSL剥离攻击？就是说人们访问站点的时候，一般都是使用的 HTTP 请求，然后再由服务端进行重定向操作，此时攻击者将用户访问的所有 HTTPS 协议的地址转为 HTTP 协议的地址，从而达到阻止HTTPS的目的，简言之就是偷偷地将目标地址换成指向指定的类似钓鱼网站等地址。</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;而 HSTS 的作用就是，当浏览器和服务端创建过一次安全连接后，之后所有的请求便都会转换成 HTTPS 协议的请求。<br></p>
<p><br></p>
<h2>三、解决</h2>

<p>&nbsp;&nbsp;&nbsp;&nbsp;我们现在的问题不是要去添加 HSTS，而是要去取消 HSTS。<br></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;从浏览器到服务端，其实中间最主要经过的就是 nginx。<br></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;1、处理 nginx<br></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;修改 nginx 的配置配置文件，发现根本就没有配置 <span style="font-size: 14px;">Strict-Transport-Security&nbsp;</span>，于是就手动添加一行配置，将时间设置为 1 秒，<br></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<img src="http://blogsource.chenkaikai.com/uploads/image/20180831/1535686972560553.png" title="1535686972560553.png" alt="reject-hsts05.png"></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;重启后发现了神奇的事情，查看 network 的时候，发现响应头信息中有两条&nbsp;<span style="font-size: 14px;">Strict-Transport-Security，又是黑人问号脸。推断其中时间为1秒的应该是nginx中的配置。</span></p>
<p><span style="font-size: 14px;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<img src="http://blogsource.chenkaikai.com/uploads/image/20180831/1535687276938022.png" title="1535687276938022.png" alt="reject-hsts06.png"></span></p>
<p><span style="font-size: 14px;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;所以，修改 nginx 配置是行不通的<br></span></p>
<p><span style="font-size: 14px;">&nbsp;&nbsp;&nbsp;&nbsp;2、终极解决之道<br></span></p>
<p><span style="font-size: 14px;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;中间又踩了一些坑，最后发现，应该是去调整服务端的响应头信息，<br></span></p>
<p><span style="font-size: 14px;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;服务端主体技术是 springBoot，安全框架是 springSecurity，然后又踩了一波坑，最后发现，其实只要调整的是&nbsp;<span style="font-size: 14px;">springSecurity 中的配置。</span></span></p>
<p><span style="font-size: 14px;"><span style="font-size: 14px;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;配置见官网，<a href="https://docs.spring.io/autorepo/docs/spring-security/3.2.0.CI-SNAPSHOT/reference/html/headers.html" target="_blank">点击链接</a>。<br></span></span></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;配置也很简单，见下图即可。<br></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<img src="http://blogsource.chenkaikai.com/uploads/image/20180831/1535688197240240.png" title="1535688197240240.png" alt="reject-hsts07.png"></p>
<p><br></p>
<h2>四、后续</h2>

<p>&nbsp;&nbsp;&nbsp;&nbsp;按照上文所述调整，理应完事大吉，但访问子域名的时候还是会有问题，这和浏览器的缓存有关系，那么此时，我们需要调整下浏览器。<br></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;此处仅以 Chrome 为例，<br></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;1、访问chrome://net-internals/#hsts</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;2、见下图操作<br></p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<img src="http://blogsource.chenkaikai.com/uploads/image/20180831/1535690627829085.png" title="1535690627829085.png" alt="reject-hsts08.png"></p>
<p><br></p>
<p><br></p>
<p><br></p>
<p><br></p>
<p><br></p>
<p><br></p>
<p><br></p>
<p><br></p>
<p><br></p>
<p><br></p>
<p><br></p>
<p><br></p>
<p><br></p>

      
    </div>

    

    
    
    
	
	<div>
	  
		<div>
    
        <div style="text-align:center;color: #ccc;font-size:14px;">------ 本文结束 <i class="fa fa-fighter-jet"></i> 感谢阅读 ------</div>
    
</div>
	  
	</div>

    

    
      
    
    

    

    <footer class="post-footer">
      
        <div class="post-tags">
          
            <a href="/tags/JavaWeb/" rel="tag"><i class="fa fa-tag"></i> JavaWeb</a>
          
            <a href="/tags/SpringBoot/" rel="tag"><i class="fa fa-tag"></i> SpringBoot</a>
          
            <a href="/tags/SpringSecurity/" rel="tag"><i class="fa fa-tag"></i> SpringSecurity</a>
          
            <a href="/tags/HSTS/" rel="tag"><i class="fa fa-tag"></i> HSTS</a>
          
            <a href="/tags/HTTPS/" rel="tag"><i class="fa fa-tag"></i> HTTPS</a>
          
        </div>
      

      
      
      

      
        <div class="post-nav">
          <div class="post-nav-next post-nav-item">
            
              <a href="/summarize-2018-08-19/" rel="next" title="近期小问题总结 2018/08/19">
                <i class="fa fa-chevron-left"></i> 近期小问题总结 2018/08/19
              </a>
            
          </div>

          <span class="post-nav-divider"></span>

          <div class="post-nav-prev post-nav-item">
            
              <a href="/springboot-log/" rel="prev" title="springBoot日志输出">
                springBoot日志输出 <i class="fa fa-chevron-right"></i>
              </a>
            
          </div>
        </div>
      

      
      
    </footer>
  </div>
  
  
  
  </article>


  </div>


          </div>
          

  



        </div>
        
          
  
  <div class="sidebar-toggle">
    <div class="sidebar-toggle-line-wrap">
      <span class="sidebar-toggle-line sidebar-toggle-line-first"></span>
      <span class="sidebar-toggle-line sidebar-toggle-line-middle"></span>
      <span class="sidebar-toggle-line sidebar-toggle-line-last"></span>
    </div>
  </div>

  <aside id="sidebar" class="sidebar">
    
    <div class="sidebar-inner">

      

      
        <ul class="sidebar-nav motion-element">
          <li class="sidebar-nav-toc sidebar-nav-active" data-target="post-toc-wrap">
            Table of Contents
          </li>
          <li class="sidebar-nav-overview" data-target="site-overview-wrap">
            Overview
          </li>
        </ul>
      

      <div class="site-overview-wrap sidebar-panel">
        <div class="site-overview">
          <div class="site-author motion-element" itemprop="author" itemscope itemtype="http://schema.org/Person">
            
              <p class="site-author-name" itemprop="name">Jet Chen</p>
              <p class="site-description motion-element" itemprop="description"></p>
          </div>

          
            <nav class="site-state motion-element">
              
                <div class="site-state-item site-state-posts">
                
                  <a href="/archives/">
                
                    <span class="site-state-item-count">68</span>
                    <span class="site-state-item-name">posts</span>
                  </a>
                </div>
              

              
                
                
                <div class="site-state-item site-state-categories">
                  <a href="/categories/index.html">
                    
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                    <span class="site-state-item-count">33</span>
                    <span class="site-state-item-name">categories</span>
                  </a>
                </div>
              

              
                
                
                <div class="site-state-item site-state-tags">
                  <a href="/tags/index.html">
                    
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                      
                    
                    <span class="site-state-item-count">182</span>
                    <span class="site-state-item-name">tags</span>
                  </a>
                </div>
              
            </nav>
          

          

          
            <div class="links-of-author motion-element">
              
                <span class="links-of-author-item">
                  
                  
                    
                  
                  
                    
                  
                  <a href="https://github.com/goldenJet" title="GitHub &rarr; https://github.com/goldenJet" rel="noopener" target="_blank"><i class="fa fa-fw fa-github"></i>GitHub</a>
                </span>
              
                <span class="links-of-author-item">
                  
                  
                    
                  
                  
                    
                  
                  <a href="https://twitter.com/goldenJ51015801" title="Twitter &rarr; https://twitter.com/goldenJ51015801" rel="noopener" target="_blank"><i class="fa fa-fw fa-twitter"></i>Twitter</a>
                </span>
              
            </div>
          

          

          
          

          
            
          
          

        </div>
      </div>

      
      <!--noindex-->
        <div class="post-toc-wrap motion-element sidebar-panel sidebar-panel-active">
          <div class="post-toc">

            
            
            
            

            
              <div class="post-toc-content"><ol class="nav"><li class="nav-item nav-level-2"><a class="nav-link" href="#undefined"><span class="nav-number">1.</span> <span class="nav-text">一、背景</span></a></li><li class="nav-item nav-level-2"><a class="nav-link" href="#undefined"><span class="nav-number">2.</span> <span class="nav-text">二、知识点</span></a></li><li class="nav-item nav-level-2"><a class="nav-link" href="#undefined"><span class="nav-number">3.</span> <span class="nav-text">三、解决</span></a></li><li class="nav-item nav-level-2"><a class="nav-link" href="#undefined"><span class="nav-number">4.</span> <span class="nav-text">四、后续</span></a></li></ol></div>
            

          </div>
        </div>
      <!--/noindex-->
      

      

    </div>
  </aside>


        
      </div>
    </main>

    <footer id="footer" class="footer">
      <div class="footer-inner">
        <div class="copyright">&copy; 2017 – <span itemprop="copyrightYear">2019</span>
  <span class="with-love" id="animate">
    <i class="fa fa-user"></i>
  </span>
  <span class="author" itemprop="copyrightHolder">Jet Chen</span>

  

  
</div>









<div class="BbeiAn-info">
    <a target="_blank" href="http://www.miitbeian.gov.cn/" rel="nofollow">浙ICP备17005575号-1</a> <!--a标签中增加nofollow属性，避免爬虫出站。-->| 
	<a target="_blank" href="http://www.beian.gov.cn/portal/registerSystemInfo?recordcode=33010802009043" style="text-decoration:none;padding-left:17px;background:url(/images/icon-police.png) no-repeat left center" rel="nofollow">浙公网安备 33010802009043号</a>	  <!--这里将图标作为了背景，以使得能和后面的文字在同一行-->
</div>

        








        
      </div>
    </footer>

    
      <div class="back-to-top">
        <i class="fa fa-arrow-up"></i>
        
          <span id="scrollpercent"><span>0</span>%</span>
        
      </div>
    

    

    

    
  </div>

  

<script>
  if (Object.prototype.toString.call(window.Promise) !== '[object Function]') {
    window.Promise = null;
  }
</script>


























  
  <script src="/lib/jquery/index.js?v=2.1.3"></script>

  
  <script src="/lib/velocity/velocity.min.js?v=1.2.1"></script>

  
  <script src="/lib/velocity/velocity.ui.min.js?v=1.2.1"></script>


  


  <script src="/js/src/utils.js?v=7.0.0"></script>

  <script src="/js/src/motion.js?v=7.0.0"></script>



  
  


  <script src="/js/src/affix.js?v=7.0.0"></script>

  <script src="/js/src/schemes/pisces.js?v=7.0.0"></script>




  
  <script src="/js/src/scrollspy.js?v=7.0.0"></script>
<script src="/js/src/post-details.js?v=7.0.0"></script>



  


  <script src="/js/src/bootstrap.js?v=7.0.0"></script>



  


  


  




  

  

  

  

  

  

  

  

  

  

  

  

  

</body>
</html>
